Processing of Criminal Conviction and Related Data, v1.0
Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 10.
Assessment Step
1
Processing of Criminal Conviction and Related Data (ProcessingofCriminalConvictionandRelatedData)
If and when the entity processes personal data relating to criminal convictions, offences, or related security measures, is the processing carried out only under the control of official authority or authorized by Union or Member State law that includes appropriate safeguards for the rights and freedoms of data subjects?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.
|
Conformance Criteria (1)
Processing of Criminal Conviction and Related Data
If the data controller processes personal data relating to criminal convictions, offences, or related security measures, then the processing must be carried out only under the control of official authority or be authorized by Union or Member State law providing appropriate safeguards for the rights and freedoms of data subjects.
Citation
GDPR
Art. 10, Recital 75
|